Search CVE reports


Toggle filters

1 – 10 of 63 results


CVE-2024-25584

Medium priority
Not affected

Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP....

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-23185

Medium priority

Some fixes available 5 of 8

Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building...

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Fixed Fixed Fixed Needs evaluation
Show less packages

CVE-2024-23184

Medium priority
Fixed

Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18...

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Fixed Fixed Not affected Not affected
Show less packages

CVE-2022-30550

Medium priority

Some fixes available 5 of 7

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver and args settings, incorrect username_filter and mechanism settings can...

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-33515

Medium priority
Fixed

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Fixed Fixed Not affected
Show less packages

CVE-2021-29157

Medium priority
Fixed

Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of...

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Fixed Not affected Not affected
Show less packages

CVE-2020-7957

Medium priority
Not affected

The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the...

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Not affected
Show less packages

CVE-2020-7046

Medium priority
Not affected

lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop.

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Not affected
Show less packages

CVE-2020-28200

Low priority
Ignored

The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension.

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Not affected Not affected Ignored Ignored
Show less packages

CVE-2020-25275

Medium priority
Fixed

Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.

1 affected package

dovecot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dovecot Fixed Fixed
Show less packages